By definition, you do not know what the client allows or not. Starting here, you have to propose a suitable alternative (undestand static way) to whatever enhancement you make in your application, except for closed and under control environment (an intranet). You cannot force user to allow js, flash, java,... in fact you can, but you will lost visitors.
Count the sites that do.... You will need more than the fingers of one hand....
Doesnt browscap.ini tell you this? Ive never used it myself, but I understand this is what its for
Security makes administrators reject a lot of web enhancement tools in many companies, we have to take care about that.
I dont think there are too many security problems in using JS/DHTML...
I think that people are becoming confused though, I was just trying to make people use document.getElementById() instead of document.all.
Personally I think that using DHTML in PEAR exts is not a problem _as_long_as_ people write it for MODERN browsers (eg v.5+). It should DEGRADE for other browsers, showing the same information and still allowing browsing of the site. TreeMenu can degrade by showing all of the trees open by default. If someone decides to extend the class later on so that it 'works' in NS4 then good for them, personally I dont concider rewriting everything else again worthwile just for the 0.01% of the _public_ that actually uses the bloody thing.
I think that we should say that any DHTML being contributed to PEAR should work on all modern browsers and degrade in text based ones... Thats not too hard is it?